Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.
In last month's issue, we elucidated the positive aspects of mHealth (use of mobile devices in a health-care setting) technology. After reviewing the examples of all the benefits mHealth technologies offer, it can be hard to imagine the downside. Yet, without the proper safeguards like the development of institutional policies, staff education and training in risks and prevention, the rapid and widespread adoption of these tools with unbridled enthusiasm carries huge risks for the patient and the provider. The two areas of greatest risk and vulnerability are the security of patient information and new ways in which mHealth may expose physicians to malpractice claims or other tort lawsuits.
Security and Privacy Breaches, and HIPAA
The Health Insurance Portability and Accountability Act (HIPAA), Public Law 104-191, 104th Congress, Aug. 21, 1996, www.hhs.gov/ocr/privacy/hipaa/administrative/statute/index.htm, 45 CFR 160, 162 and 164, passed by Congress in 1996, provides both rights and protections for group health plan members, including a mandate that covered entities keep patient records secure and accessible only to authorized parties. The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 extends these protections to the electronic transmission of electronic health information (the security regulations are found at 45 C.F.R. parts 160 and 164, subpart C (Security Rule); the privacy regulations are found at 45 C.F.R parts 160 and 164, subpart E (Privacy Rule)).
Security and Privacy Breaches
Security and privacy go hand-in-hand: keeping patient records secure keeps patient privacy intact. Securing health records has always been a challenge, but it turns out to be even more difficult as paper records go digital and become both portable and transmittable.
Concerns about security breaches are getting a lot of attention these days both in and out of the health care industry. Data breaches run the gamut from sophisticated hacking to simple human error. Take the cyber theft of personal data of about 100 million Sony Customers earlier this year. It's not just a public relations nightmare ' as of this writing there are at least 25 lawsuits against Sony related to the breach in the works. “Data breach suit grows, but damaged hard to prove,” Business Insurance, May 12, 2001 www.businessinsurance.com/article/20110512/NEWS01/110519979. But it doesn't take a cyber attack to be exposed to huge financial penalties. Massachusetts General Hospital recently agreed to a $1 million settlement to satisfy a HIPAA violation when an employee left paper patient records on a subway train. “Massachusetts General Hospital Settles Potential HIPAA Violations,” U.S. Dept. of Health & Human Services news release, Feb. 24, 2011, www.hhs.gov/news/press/2011pres/02/20110224b.html. Obviously, even a small breach can have a stiff penalty.
HIPAA Breaches
The U.S. Department of Health and Human Services website lists HIPAA security breaches affecting 500 or more people. As of May 29, 2011, there have been 278 breaches of this size, ranging from incidents of loss, theft, unauthorized access, disclosure, hacking or IT incidents and improper disposal. Of these 278 breaches, 48 involved loss, and 22 of those losses involved a portable electronic device. 57 of the 278 breaches involved theft and 75 breaches involved laptops (almost all of them theft). “Breaches Affecting 500 or More Individuals, U.S. Dept. of Health & Human Services, www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html.
The following true-life cases give an idea of the kinds of breaches that can occur when computers and mobile devices are used in the health care setting:
And consider this: It is much easier to lose a smartphone, BlackBerry or tablet than it is to lose a paper record, entire computer or hard drive. So it is inevitable that as the use of these devices in the medical workplace skyrockets, data breaches and security compromises will occur. Echoing this point, an executive for Diversinet (which produces secure mobile platforms for use with healthcare apps) has recommended that not only should the data be encrypted but that apps should be able to be deactivated or deleted if a mobile device is lost, similar to the way lost credit cards are deactivated by banks. Versal, Neil, “How Mobile Health Can Abide by HIPAA, Apr 20, 2011, http://mobihealthnews.com/10747/how-mobile-health-can-abide-by-hipaa/.
Medical Malpractice
Although HIPAA's Privacy and Security Rules are designed to protect patients, a violation is not grounds for a lawsuit by an individual. All complaints are filed with the U.S. Department of Health and Human Services' Office for Civil Rights (OCR), which investigates and metes out penalties. However, the changes mHealth technologies bring to the way hospitals and physicians work go beyond security and privacy concerns and have implications for how malpractice suits are handled.
It is only a matter of time before the use of medical apps on mobile devices is a factor in a malpractice lawsuit. We can guess at some of the issues their use will raise:
Conclusion
For now, lawyers have a new set of questions to ask in discovery ' of their own clients and of the opposition:
The use of any technology has its growing pains, and mHealth will be no different. However, until issues of privacy and security can be addressed, it would be best for physicians to limit their use of mHealth to nonconfidential communications. The risks currently outweigh the benefits.
Linda S. Crawford, a member of this newsletter's Board of Editors, teaches trial advocacy at Harvard Law School and has been consulting with defendants on research-based effectiveness at deposition and trial since 1985.
In last month's issue, we elucidated the positive aspects of mHealth (use of mobile devices in a health-care setting) technology. After reviewing the examples of all the benefits mHealth technologies offer, it can be hard to imagine the downside. Yet, without the proper safeguards like the development of institutional policies, staff education and training in risks and prevention, the rapid and widespread adoption of these tools with unbridled enthusiasm carries huge risks for the patient and the provider. The two areas of greatest risk and vulnerability are the security of patient information and new ways in which mHealth may expose physicians to malpractice claims or other tort lawsuits.
Security and Privacy Breaches, and HIPAA
The Health Insurance Portability and Accountability Act (HIPAA), Public Law 104-191, 104th Congress, Aug. 21, 1996, www.hhs.gov/ocr/privacy/hipaa/administrative/statute/index.htm, 45 CFR 160, 162 and 164, passed by Congress in 1996, provides both rights and protections for group health plan members, including a mandate that covered entities keep patient records secure and accessible only to authorized parties. The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 extends these protections to the electronic transmission of electronic health information (the security regulations are found at 45 C.F.R. parts 160 and 164, subpart C (Security Rule); the privacy regulations are found at 45 C.F.R parts 160 and 164, subpart E (Privacy Rule)).
Security and Privacy Breaches
Security and privacy go hand-in-hand: keeping patient records secure keeps patient privacy intact. Securing health records has always been a challenge, but it turns out to be even more difficult as paper records go digital and become both portable and transmittable.
Concerns about security breaches are getting a lot of attention these days both in and out of the health care industry. Data breaches run the gamut from sophisticated hacking to simple human error. Take the cyber theft of personal data of about 100 million Sony Customers earlier this year. It's not just a public relations nightmare ' as of this writing there are at least 25 lawsuits against Sony related to the breach in the works. “Data breach suit grows, but damaged hard to prove,” Business Insurance, May 12, 2001 www.businessinsurance.com/article/20110512/NEWS01/110519979. But it doesn't take a cyber attack to be exposed to huge financial penalties.
HIPAA Breaches
The U.S. Department of Health and Human Services website lists HIPAA security breaches affecting 500 or more people. As of May 29, 2011, there have been 278 breaches of this size, ranging from incidents of loss, theft, unauthorized access, disclosure, hacking or IT incidents and improper disposal. Of these 278 breaches, 48 involved loss, and 22 of those losses involved a portable electronic device. 57 of the 278 breaches involved theft and 75 breaches involved laptops (almost all of them theft). “Breaches Affecting 500 or More Individuals, U.S. Dept. of Health & Human Services, www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html.
The following true-life cases give an idea of the kinds of breaches that can occur when computers and mobile devices are used in the health care setting:
And consider this: It is much easier to lose a smartphone, BlackBerry or tablet than it is to lose a paper record, entire computer or hard drive. So it is inevitable that as the use of these devices in the medical workplace skyrockets, data breaches and security compromises will occur. Echoing this point, an executive for Diversinet (which produces secure mobile platforms for use with healthcare apps) has recommended that not only should the data be encrypted but that apps should be able to be deactivated or deleted if a mobile device is lost, similar to the way lost credit cards are deactivated by banks. Versal, Neil, “How Mobile Health Can Abide by HIPAA, Apr 20, 2011, http://mobihealthnews.com/10747/how-mobile-health-can-abide-by-hipaa/.
Medical Malpractice
Although HIPAA's Privacy and Security Rules are designed to protect patients, a violation is not grounds for a lawsuit by an individual. All complaints are filed with the U.S. Department of Health and Human Services' Office for Civil Rights (OCR), which investigates and metes out penalties. However, the changes mHealth technologies bring to the way hospitals and physicians work go beyond security and privacy concerns and have implications for how malpractice suits are handled.
It is only a matter of time before the use of medical apps on mobile devices is a factor in a malpractice lawsuit. We can guess at some of the issues their use will raise:
Conclusion
For now, lawyers have a new set of questions to ask in discovery ' of their own clients and of the opposition:
The use of any technology has its growing pains, and mHealth will be no different. However, until issues of privacy and security can be addressed, it would be best for physicians to limit their use of mHealth to nonconfidential communications. The risks currently outweigh the benefits.
Linda S. Crawford, a member of this newsletter's Board of Editors, teaches trial advocacy at
ENJOY UNLIMITED ACCESS TO THE SINGLE SOURCE OF OBJECTIVE LEGAL ANALYSIS, PRACTICAL INSIGHTS, AND NEWS IN ENTERTAINMENT LAW.
Already a have an account? Sign In Now Log In Now
For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473
With each successive large-scale cyber attack, it is slowly becoming clear that ransomware attacks are targeting the critical infrastructure of the most powerful country on the planet. Understanding the strategy, and tactics of our opponents, as well as the strategy and the tactics we implement as a response are vital to victory.
In June 2024, the First Department decided Huguenot LLC v. Megalith Capital Group Fund I, L.P., which resolved a question of liability for a group of condominium apartment buyers and in so doing, touched on a wide range of issues about how contracts can obligate purchasers of real property.
The Article 8 opt-in election adds an additional layer of complexity to the already labyrinthine rules governing perfection of security interests under the UCC. A lender that is unaware of the nuances created by the opt in (may find its security interest vulnerable to being primed by another party that has taken steps to perfect in a superior manner under the circumstances.
Latham & Watkins helped the largest U.S. commercial real estate research company prevail in a breach-of-contract dispute in District of Columbia federal court.